Last updated: September 2026
Privacy Policy
This policy explains what information Ordingo collects, how we use it, and the choices you have. It applies to venue owners and staff who create an Ordingo account, and to guests who place an order through a venue running on Ordingo.
Who we are
Ordingo is a QR-code ordering and venue-management platform used by restaurants, bars, and other counter-service venues. In this policy, "Ordingo," "we," or "us" refers to the operator of the platform; "venue" refers to a business using Ordingo to take orders; "guest" refers to a customer of that venue placing an order.
Information we collect
Account and venue information: when a venue signs up, we collect the venue name, menu URL slug, and the admin's email address and password (stored as a salted hash, never in plain text). Billing details are collected and stored by Stripe on our behalf — we never see or store full card numbers.
Staff information: names, email addresses, and role/permission settings for staff accounts a venue creates.
Guest order information: the items ordered, the table/seat or QR code used, order status and timestamps, and any optional note added to an order. Placing an order does not require creating an account, and we do not ask guests for a name or email unless the venue's own order-notes field is used to provide one voluntarily.
Usage and device data: standard server logs (IP address, browser type, pages requested) generated by operating the service. For staff and admin accounts specifically, we also keep a security log of sign-in activity (successful and failed login attempts) together with the IP address and device/browser information of the request, so we can investigate suspicious access to a venue's account. This security log is visible only to Ordingo's own platform administrators, not to the venue's own staff.
Cookies and local storage: used in the guest's own browser to remember a language preference, the current cart, and links back to an order's status or a seat's tab — this data lives on the guest's device, not in a Ordingo account.
How we use information
To operate the ordering platform: taking orders, routing them to kitchen/bar displays, and tracking status in real time.
To process payments, through Stripe, for both a venue's subscription and a guest's card payment where a venue has card payments enabled.
To send transactional email (account confirmations, receipts, service notices) through our email provider, Resend.
To provide the optional AI menu-import and AI-translation features: a photo, PDF, or text a venue submits is sent to one or more third-party AI providers we work with (currently Google) solely to extract or translate menu categories, items, prices, and descriptions — it is not used to train any model. We may add, remove, or switch AI providers over time as the underlying technology changes.
To communicate with venue owners about their account, and to maintain the security and reliability of the service.
How we share information
We share information with the service providers that help us run Ordingo: Stripe (payments), Resend (email delivery), our AI provider(s) (currently Google, subject to change — see above), and our cloud hosting provider — each processes data only as needed to provide their part of the service.
We may disclose information if required by law, or to protect the rights, property, or safety of Ordingo, our venues, or the public.
We do not sell guest or venue data to third parties.
Data retention
Account and venue data is kept for as long as the account is active, and for a reasonable period afterward for accounting and legal record-keeping. Guest order data is retained for the same accounting purposes and is not linked to an identifiable guest unless the guest provided their own details in an order note.
Your rights
Depending on where you're located, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us at the address below.
Security
We use reasonable technical and organizational measures to protect information, including encryption in transit and hashed passwords. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
If we become aware of a security incident affecting your personal data, we'll notify affected venues without undue delay and take reasonable steps to investigate and address it — the detailed processor obligations that apply to guest order data are set out in our Data Processing Agreement.
International transfers
Our service providers may process data in countries other than your own, including outside the European Economic Area. Where that happens, we implement an appropriate transfer mechanism under applicable data-protection law — such as the European Commission's Standard Contractual Clauses, or another lawful safeguard the receiving provider offers — before the transfer takes place.
Children's privacy
Ordingo is intended for business use and is not directed at children under 16.
Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last revised; material changes will be communicated to venue admins by email.
Contact us
Questions about this policy can be sent to hello@ordingo.app.